Built for enterprise security

Security controls and deployment flexibility designed for enterprise use.

Security

Access Management
SSO, MFA and least-privilege access help restrict data and systems to the right users.
Vulnerability management
Regular vulnerability scanning, risk-based remediation and security patching help identify and address weaknesses.
Monitoring
Production systems and security-relevant events are logged and monitored, with alerts for events requiring investigation.
Continuous integration
Automated build, testing and staging checks are integrated into the development pipeline before production releases.

Infrastructure

Cloud infrastructure
Platonic-managed deployments run on AWS with infrastructure-level access and network protections.
Environment segregation
Production, staging and development environments are separated through infrastructure and access controls.
Secure configuration
Infrastructure follows secure configuration baselines informed by recognized standards and cloud-provider best practices.

Governance

SOC 2 program
Platonic is actively completing its SOC 2 compliance program.
Policies
Formal security policies define responsibilities and expected practices across the organization.
Risk management
Regular risk assessments and vendor reviews identify and prioritize security risks across Platonic and its third parties.
Incident response
Defined procedures cover investigation, containment, remediation and escalation of security incidents.

Privacy

Recording controls
Users can pause and resume recording, exclude specific applications and choose which recordings they share.
Data minimization
Platonic captures workflow signals without recording typed text, clipboard contents, audio, camera input or continuous video.
GDPR program
Platonic is actively completing its GDPR compliance program.

Deployment

Flexible infrastructure
Deploy on Platonic-managed infrastructure, infrastructure of your choice, or fully on-premises.
Fast rollout
The lightweight endpoint application can be installed from a secure link and typically set up in minutes.

Data Protection

Encryption
Customer data is encrypted in transit and at rest across storage, service communications and backups.
Backup & recovery
Production data is backed up, encrypted and covered by tested recovery procedures.

Frequently Asked Questions

What data does Platonic capture from employee devices?

Platonic captures periodic screenshots and interaction metadata needed to reconstruct workflows, including clicks, scrolling, shortcuts, and application activity. It does not record typed text, clipboard contents, audio, camera input, or continuous video. Recording sessions remain visible to users and can be paused, reviewed, or deleted at any time.

What security standards does Platonic follow?

Platonic follows a formal information security program covering access control, encryption, vulnerability management, monitoring, incident response, business continuity, vendor management, and employee security training. We are currently completing our SOC 2 compliance programs. For more detail, including policies, controls, subprocessors, and compliance status, visit our Trust Center.

How do you handle employee privacy?

Platonic acts as a data processor for employee data, processing it only on the customer’s instructions and under safeguards covering confidentiality, security, subprocessors, retention, and support for data subject rights. We are actively completing our GDPR compliance program. Beyond these requirements, Platonic includes additional privacy controls: users can pause and resume recording, exclude specific applications from capture, and choose which recordings they share.

What does the deployment journey look like?

Deployment is designed to be fast and flexible. Customers can use Platonic-managed infrastructure, deploy on infrastructure of their choice, or run fully on-premises; customer-managed and on-premises setups are typically lightweight and mainly require coordination with the customer’s IT team. End users then install a lightweight application from a secure link and can authenticate through credentials or SSO, with setup typically taking only minutes.

Where does our data go, and who can access it?

Customer data handling is designed to be flexible. Customers can choose where Platonic runs, where data is stored, and whether analysis is performed through external AI infrastructure or within their own environment. Access can be configured to match customer requirements, including setups where data remains entirely within customer-controlled infrastructure and is accessible only to authorized customer users.